Govern AI, from inventory to trusted action.

Account for every model and agent, assess risk, apply controls and collect evidence. Deploy AI workflows faster and confidently answer to regulators, boards and customers.

Northwind Mutual ⌄Console › HomeSearch ⌘KProductionModelPolling

AI governance overview

Northwind Mutual, all business units. Updated 2 minutes ago.

Last 30 days ⌄Board report
AI systems148+5 this week
High risk232 without an owner
Controls evidenced43 of 81+6 this month
Decisions today3,91237 blocked

Governance posture by business unit

StrongPartialNone
InventoryRiskControlsAssuranceAuthority
ClaimsStrongGoodGoodPartialGood
UnderwritingStrongPartialPartialWeakNone
Customer ServiceGoodGoodPartialPartialNone
FinanceStrongPartialWeakWeakNone
TechnologyPartialWeakWeakNoneNone

Needs attention

7
  • HighUnknown gpt-4o caller in Finance has no owner
  • HighControl test failed: claims payment threshold
  • MediumUnderwriting risk summariser review due in 3 days

Frameworks

81 controls
  • CPS 230
  • CPS 234
  • FAR

Claims

Business unit summary

Open
AI systems326 high risk
Controls in place24 of 29+3 this month

Governance by stage

Inventory100%
Risk91%
Controls83%
Assurance58%
Authority4 agents

Runtime decisions today

2,810 allowed9 approval21 blocked

Top risks

Claims triage agentPayment threshold test failedHigh
Fraud signal modelBias test due in 5 daysHigh
Claims letter drafterOwner leaving, reassignMedium

Accountable executive: Chief Claims Officer (FAR)

1Discover

Know what AI exists before you govern it

One inventory of models, agents, endpoints, copilots and MCP servers, built from what teams register and what Cogna8 finds on connected platforms.

  • Declared and discovered side by side, with unmanaged AI flagged
  • A copilot triages new finds and waits for your approval
  • Owner, business unit, risk and control coverage on every row
  • Sources, usage and last-seen kept current

The question it answers: What AI do we have, and who owns it?

Northwind Mutual ⌄Console › Inventory › DiscoverySearch ⌘KCopilotProductionModelPolling

Discovery

7 AI systems found since the last review, not yet registered.

FiltersRun discovery
Found this week7Since 24 Sep
Unowned2Needs an owner
Possible duplicates2Of registered systems
Sources scanned4 of 5Synced 6h ago
AssetSourceOwnerRiskStatus
Unknown gpt-4o callerObserved trafficTelemetryNoneR. SinghHighUnownedOwner proposed
Claims letter drafterCopilotM365NoneJ. PatelMediumNot registeredRegistration drafted
quote-helperBedrock agentAWS BedrockS. OkaforMediumNot registeredMatched UW-114
fraud-v2Serving endpointDatabricksR. LindqvistHighNot registeredMerged
chat-test-3Model deploymentAzure AI FoundryNoneLowIdle 41 daysRetire proposed
Claims triage agentAgentAWS BedrockJ. PatelHighGated
Fraud signal modelModelDatabricksR. LindqvistHighEvidenced
CopilotInventory · Discovery×
Working onTriage 7 newly discovered AI systems
  1. Matched 2 to existing systems
  2. Found owners from cloud tags and the directory
  3. Drafted 1 registration from the Copilot catalogue
  4. Waiting on 3 decisions from you
  5. Request risk assessments for new systems
Needs your approval
Assign owner to Unknown gpt-4o callerFinance cost centre FIN-22 · tag owner=rsingh

R. Singh becomes the accountable owner and gets a review task.

ApproveEditSkip
✓Approved by Alex Morgan · receipt rcpt_9K2D41
Register Claims letter drafterFound in Microsoft 365 Copilot agents

Create the record with owner J. Patel, tier Medium (proposed).

ApproveEditSkip
1 more waiting below
Each action runs through the Cogna8 gate and leaves a receipt.
Ask about this screen or give an instruction↵
2Assess

Who is accountable, and what can go wrong

Each AI system is scored on the dimensions that matter to a regulated business, with an accountable executive and a review date that follows the tier.

  • Six risk dimensions with a clear tier rule
  • Reassessed when a release changes what an agent can do
  • Inherent and residual risk on one matrix
  • Accountability aligned to FAR key functions

The question it answers: How risky is it, and who answers for it?

Northwind Mutual ⌄Console › Risk › Risk assessments › Underwriting risk summariserSearch ⌘KCopilotProductionModelPolling

Underwriting risk summariser

Serving endpoint on Databricks. Version 2.3 released 28 Sep 2026.

High riskHistory
OverviewRiskControls 6Cyber 2Evidence 11Runtime

Risk dimensions

2 proposed changes
Data sensitivity5
Autonomy23
2 → 3 Approves quotes under $5k without review since v2.3
External actions12
1 → 2 Can now email brokers (tool added 28 Sep, change CR-4471)
Financial impact4
Customer impact4
Critical system access3

What changed in v2.3

  • MediumNew tool: send email to broker
  • HighAuto-approve quotes under $5,000
  • LowModel upgraded, same provider

Controls

4 of 6 in place
Evidenced OR-12 Change control for models
OR-07 Provider due diligence
OR-15 Human approval above threshold
CopilotRisk · Underwriting risk summariser×
Working onReassess Underwriting risk summariser after v2.3
  1. Read change CR-4471 and the v2.3 release notes
  2. Compared tool access before and after
  3. Checked 1,204 decision receipts from 30 days
  4. 2 score changes need your confirmation
  5. Update required controls for the new scores
Needs your approval
Raise autonomy from 2 to 3Source: v2.3 release notes · 412 auto-approvals

Tier stays High. Adds control OR-15, human approval above threshold.

ConfirmEditSkip
✓Confirmed by Alex Morgan · version 7 saved
Raise external actions from 1 to 2Source: CR-4471 · email tool added

Adds a tool permission review and an outbound email control.

ConfirmEditSkip
Scores change only when a person confirms. Every change is versioned.
Ask why, or point at a dimension↵
3Control

Obligations turned into operational controls

Frameworks live in a versioned control registry. Each control has an owner, the AI systems it governs and an implementation level you can defend.

  • CPS 230, CPS 234 and FAR in the registry today
  • Coverage by framework at a glance
  • Every control linked to the systems it governs

The question it answers: Which controls apply, and are they in place?

Northwind Mutual ⌄Console › Controls › Control portfolioSearch ⌘KProductionModelPolling

Control portfolio

81 controls across 3 frameworks, mapped to 148 AI assets.

Map controlAssign owners

Frameworks

3
  • CPS 230 Operational Risk ManagementAPRA, 41 controls
  • CPS 234 Information SecurityAPRA, 24 controls
  • FAR, Insurance Key FunctionsAPRA and ASIC, 16 controls
EvidencedImplementedIn progressNot started
76%in place
31 of 41 CPS 230 controls implemented or evidenced. 4 not started.

CPS 230 Operational Risk Management

F2026L00475Available
IDControlOwnerAssetsImplementationEvidence
OR-01Critical operations and AI dependencies mappedChief Risk Officer12Evidenced3
OR-07Third-party AI provider due diligenceProcurement91
OR-12Change control for AI models in productionHead of Platform31Evidenced2
OR-15Human approval above payment thresholdsClaims Ops Lead4Evidenced2
OR-21AI incident escalation to operational riskOperational Risk148Implemented1
OR-26Tolerance levels for AI-supported critical operationsChief Risk Officer0Not started0
OR-28Business continuity for AI-dependent servicesHead of Resilience6Implemented1
OR-31Service provider register includes AI vendorsProcurement14Evidenced2
OR-34Board reporting on AI operational riskCompany Secretary01
4Assure

Evidence that supports the claim, and no more

Evidence flows in from Cogna8 and from the tools you already use. Each control climbs from declared to effective only as the record supports it.

  • Assurance level by framework
  • Audit packs assembled by the copilot, sent only with approval
  • Exceptions surfaced with owners
  • Audit packs built from live evidence

The question it answers: What can we prove to an auditor today?

Northwind Mutual ⌄Console › Assurance › Audit packs › CPS 230 Q3 2026Search ⌘KCopilotProductionModelPolling

CPS 230 audit pack, Q3 2026

1 July to 30 September 2026. Draft, 82% complete.

Preview packExport
Controls in scope41All CPS 230
Evidenced or better35+6 this quarter
Gaps4Owners not yet asked
Failed tests1OR-15
IDControlProof levelEvidence
OR-01Critical operations mapped Evidenced3
OR-07Third-party AI due diligence Request drafted0
OR-12Change control for models Tested2
OR-15Human approval above threshold Request draftedTest failed1,204
OR-21AI incident escalation Evidenced4
OR-28Continuity for AI services Request drafted1
CopilotAssurance · Audit packs×
Working onBuild the CPS 230 audit pack for Q3
  1. Collected evidence for 41 controls, July to September
  2. Linked 1,204 decision receipts to OR-15
  3. Found 4 gaps and 1 failed test
  4. Send 3 evidence requests to owners
  5. Draft the exceptions summary for the committee
Needs your approval
Request evidence from ProcurementOR-07 · no third-party review since June

Email and task to the control owner, due 10 Oct.

SendEditSkip
✓Sent by Alex Morgan · task created, due 10 Oct
Raise exception for OR-152 payments approved above threshold without an approver

Opens an exception owned by the Claims Ops Lead.

RaiseEditSkip
2 more waiting below
Nothing is sent or raised without your approval.
Ask what is missing, or change the period↵
5Authorise

For consequential actions, governance becomes executable

When a governed agent proposes an action, Cogna8 checks the current state, the controls and any approval required, then allows or blocks it before it runs.

  • Every action evaluated before it runs
  • Approval routing when a person must decide
  • A replayable receipt for every decision

The question it answers: Is this action authorised, right now?

Northwind Mutual ⌄Console › Authorisation › DecisionsSearch ⌘KProductionModelPolling

Decisions

Every action evaluated by the gate before it ran.

Last 24 hours ⌄
Evaluated3,9129 governed agents
Needs approval124 waiting over 1h
Blocked3721 state conflicts

Decisions per hour

AllowedNeeds approvalBlocked
00:0004:0008:0012:0016:0020:00
TimeAgentActionDecision
14:23:07Claims triage agentRelease settlement payment, $48,200Blocked
14:22:41Claims triage agentRequest missing documentAllowed
14:22:12Broker email drafterSend renewal terms to brokerApproval
14:21:58Customer reply assistantClose complaint ticketAllowed
14:21:30Fraud signal modelFlag claim for investigationAllowed
14:20:12Claims triage agentUpdate claim reserve, $120,000Approval
14:19:47Underwriting risk summariserPublish risk note to policy fileBlocked

Decision rcpt_7Q2K9F

Blocked

Claims triage agent, 14:23:07 AEST

  1. Action proposedRelease payment of $48,200 on claim 88214
  2. State checkedClaim amount conflicts: $48,200 and $41,750
  3. Controls evaluatedOR-15 Human approval above threshold, CPS 230
  4. Approval requiredClaims Ops Lead, requested 14:23:08
  5. DecisionBlocked until the amount is resolved and approved
Policy
payments.clean_state v3
Replay
Same inputs, same decision
Export receiptOpen approval
How it works

Light entry, deep control

Most organisations start by asking what AI they have. Cogna8 answers that first, then carries the same record through to the moment an agent acts.

Frameworkclause, version Controlwith an owner AI systemrisk tiered Agentconnected Actionrequested Gatepolicy and state Decisionallow or block Evidencereceipt kept

Start with governance visibility. Inventory, ownership, risk and controls deliver value with no change to how your AI runs.

Expand into enforceable governance. Connect an agent to the gate and its controls become decisions, not documents.

Why now

AI is moving faster than the way it is governed

No one has the full list

Models and agents arrive through every team and vendor. Most organisations cannot say what is running, or who owns it.

Governance stops at paper

Policies and registers describe intent. They rarely connect to the systems doing the work, or prove what happened.

Agents now act

Once AI sends payments, changes records or emails customers, review after the fact is too late. Authority has to be checked first.

Frameworks

Deep in Australian regulation, built for global frameworks

Frameworks in the control registry carry their source instrument, version and regulator, mapped control by control. More are being added.

Who it is for

One record, three teams

Start with visibility

A short, scoped pilot on your own AI estate. Value from the inventory first, with runtime authority added only where an agent needs it.

  1. Connect or register your first AI systems
  2. Agree owners, risk tiers and the frameworks in scope
  3. Map controls and collect first evidence
  4. Optionally, put one agent behind the gate